T08 · Insecure Dependencies
- Location
package.json:8- Finding
Automatic Installation of Unpinned Python Dependency
- Content
View full analysis
=0.14.0 ``` ### Technical Analysis The npm `postinstall` lifecycle script automatically creates a Python virtual environment and installs dependencies whenever the package is installed. The `gkeepapi` dependency is specified with an open-ended lower-bound constraint rather than an exact, audited version. No lock file, upper version bound, or package hashes are provided. Consequently, pip may resolve a newer `gkeepapi` release or changed transitive dependencies that were not reviewed with this project. If an allowed dependency release or its distribution infrastructure is compromised, malicious installation hooks or runtime code can execute with the privileges of the user installing or running the package. This is a supply-chain weakness rather than evidence that the current `gkeepapi` package is malicious. ### Attack Path 1. An attacker compromises a future permitted `gkeepapi` release, one of its transitive dependencies, or the relevant package distribution channel. 2. The attacker publishes malicious package code under a version satisfying `>=0.14.0`. 3. A user installs or reinstalls this npm package. 4. npm automatically invokes the `postinstall` command. 5. pip resolves and installs the compromised dependency because the project does not pin versions or verify artifact hashes. 6. Malicious installation or runtime code executes with the installing user's privileges. 7. The malicious code can access files and data available to that user, including the Google Keep token stored under `~/.config/gkeep/token.json`. ### Impact Assessment Successful exploitation provid ...[truncated 624 chars]- Remediation
View remediation
``` 2. Generate and commit a fully resolved lock file covering all transitive Python dependencies. 3. Use hash verification, such as pip's `--require-hashes`, and record approved hashes for every installed artifact. 4. Configure installation to use an explicitly trusted package index and disable unapproved supplemental indexes to reduce dependency-confusion exposure. 5. Remove automatic pip installation from npm `postinstall` where practical. Provide an explicit setup command so dependency installation is visible and intentional. 6. Regularly review and update pinned dependencies through a controlled process that includes vulnerability scanning, provenance verification, and testing. 7. Consider installing dependencies from prebuilt, verified artifacts and rejecting unexpected source distributions that may execute build hooks. ]]>
